CVE-2026-47366 PUBLISHED

Assigner: hackerone
Reserved: 19.05.2026 Published: 12.06.2026 Updated: 12.06.2026

Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated administrator to grant permissions beyond the level authorized for their account, resulting in privilege escalation within the administrative interface.

Metrics

CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.2

Product Status

Vendor phpBB
Product phpBB
Versions Default: unaffected
  • affected from 3.3.0 to 3.3.16 (incl.)

References

Problem Types

  • CWE-284 Improper Access Control - Generic CWE